WordPress Plugin Vulnerabilities

Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload

Description

The plugin does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

Proof of Concept

Affects Plugins

Fixed in 1.3.79

References

Miscellaneous

Original Researcher
Fioravante Souza
Submitter
Fioravante Souza
Verified
Yes

Timeline

Publicly Published
2023-10-09 (about 2 years ago)
Added
2023-10-09 (about 2 years ago)
Last Updated
2023-10-09 (about 2 years ago)

Other